Cookie banners, cookie notices, GDPR notices or Privacy Notices… call them what you want. (We’ve even heard them called “that boring legal notice,” but more on that later.)
In fact, all the world’s largest and most serious companies have already added a cookie banner to their website, and this is for a good reason: GDPR, LGPD, CCPA and many others are live!
Completely inspired by the GDPR ,the LGPD in Brazil, as it’s commonly known, is a regulation that was created in 2018 specifically to address the way that personal data, such as a user’s name, e-mail, telephone number, address, etc., is collected and utilized by companies.
Why does the GDPR require cookie banners? Does every website now need a banner?
The LGPD, as said, was inspired by the European Union’s General Data Protection Regulation (GDPR), and similar laws are already being enacted all over the world. Even North Korea now has its own privacy regulation! That is to say, this is not a passing trend and must be taken seriously.
This shift does not necessarily mean more bureaucracy, but it does mean real empowerment. Thanks to these new privacy laws, ordinary citizens now have the right to authorize, deny, or even revoke companies’ ability to use their data!
Don’t worry, we can explain!
The answer is not that simple, as this law needs to function in parallel with innumerable others that also govern individual rights, including consumer, health, and internet law, among others.
Keep going, it will be worth it! Soon you’ll be able to speak like an expert on this subject.
With the advancement of advertising technologies that are linked to digital marketing and the exponential growth of social media, everyone now has a machine that generates and stores valuable data in the palm of their hands: cellphones. Every time an individual accesses a website, e-commerce account, Instagram, Facebook, or any similar platform, the visit generates data that is collected and stored by cookies.
Cookies are simply text files that are capable of storing information generated by websites.
I'm sure you know when you enter a website through your browser and it recognizes that you’ve already accessed the page before, allowing you to re-enter the site without signing in again? This happens because your browser has already stored a cookie from that site which can authorize your access.
In the same way, cookies can also store data like which photos you’ve liked on Instagram or if you “forgot” a product in your shopping cart. All of this information is saved for later use.
Did you know that a person needs, on average, at least six interactions with a product or service before making the decision to purchase?
It’s no wonder that when you “forget something in your shopping cart,” the product seems to follow you all over the internet with ads. Only then do you end up making the purchase. Is this a coincidence, or magic?
Neither, these are the processes and technologies that utilize cookies for advertising.
If you’ve been through this, welcome! You’re in good company.
Simply put, cookies are a piece of the wheel that moves the internet. It’s the use of data for advertising that allows us to consume the content that we love for free. After all, who do you think pays for that cool, free YouTube video? Advertisers! And now you know they use cookies to find you on your favorite channel.
The use of cookies is not necessarily positive or negative, but it reached a point where individuals like you or I were not fully in control of what the internet giants were doing with our data. This is why privacy laws like the GDPR, LGPD and CCPA were created: to rebalance the relationship between companies and people.
Ok, but weren’t you going to talk about data, privacy, and the rights I have?
Yes! When the LGPD was enacted by Brazil in August of 2020 it forced companies to examine the way that they handled the plethora of consumer data generated by their business, and to make changes to their processes and databases. One of these changes was the obligation to inform visitors of the reason for their data collection, as well as the legal basis for it.
Thus, in accordance with the LGPD, GDPR, CCPA and several others, every business must present a clear and objective communication that informs visitors of their purposes for collecting personal data. Whether on or offline, it is essential that every citizen is notified of the collection of their personal data as well as the many ways it might be used.
As for us data “subjects,” as some law refers to us, we are now able to make a “free, informed, and unequivocal declaration,” as to whether or not we permit its use. That is to say, if we consent to the terms outlined by the business, we authorize them to use our data.
In Brazil, for example if businesses violate this flow by collecting data without consent, they could face serious consequences including being fined up to 2% of their annual revenue, with a ceiling of 50 million real. Has your business ever considered the threat of being fined simply for not having a cookie banner on its website?
Want to understand exactly how the GDPR, LGPD and CCPA impact your business? Here are some articles on the subject.
Who among us has actually read the privacy policy or terms of use of a website we use? Not many, but it’s precisely in these official documents that these answers are found.
According to the Privacy Laws, businesses must comply with certain official documentation requirements and legal basis to inform users of their entire data collection process and its purposes. Well-known by lawyers, the “Privacy document kit” fulfills the standard that every company must meet, including a privacy policy, terms of use, data mapping, and contact information of the DPO, among others.
These documents don’t need to be written in “legalese,” nor should they be, as LGPD, GDPR and CCPA requires that the information presented be “clear and accessible.” A user cannot consent to the collection of their data if they cannot understand the banner.
What’s the use of a company acting cool in its marketing and communications, or speaking beautifully in advertisements, if when addressing privacy and transparency it starts speaking in code? It doesn’t make sense, right?
Anyway, this article aims to inform you that, along with the laws like GDPR, LGPD and CCPA, we also have new rights and duties, both as citizens and, especially, as companies. In this matter, the cookie banners actually serve a noble purpose! Businesses that use these banners correctly are able to show customers that they care about their individual rights, freedom of choice, and privacy.
Inform users clearly and objectively of all of the ways in which the company collects consumer data.
Point to official documents such as the privacy policy, terms of use, etc. (referring back to the Privacy document kit mentioned above).
List the options that you as the data owner have to fully or partially accept “the rules of the game” with that company, thus allowing you to receive their content or consume their products or services.
Make it clear where, upon accepting the cookies, you could access the data that the company will gather about you, and how to opt-out if you change your mind.
Allow users to consent to the data collection in a way that is free, informed, and unambiguous.
When you see the banner: “If you continue browsing, we understand that you consent…” know that the law has determined this to be insufficient, and there are several arguments why. Mainly, this banner without further detail does not give the visitor enough information to give their consent in a manner that is “free, informed, and unambiguous.”
We hope this article helped you to understand the “why” of the now popular cookie banners, which will soon be installed on all company websites. With this new regulation, there is no going back.
Again, any and all companies that collect personal data, such as name, email, or telephone number on their site, and use third-party services like the Facebook pixel, Google Analytics, etc. MUST include this banner.
We at AdOpt are experts in cookie banners and can help them today! And even better, for many it’s free! Send this article to whoever you know that could use this content. They will thank you when they avoid an unpleasant fine!
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
While both regulations share the goal of safeguarding individuals' rights regarding the processing of their personal data, there are some important differences between them. It is crucial to understand these distinctions and their implications, particularly in the context of internet cookies.
In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
On October 18, 2022, the National Data Protection Authority (ANPD) released the "Guidance on Cookies and Personal Data Protection." Highly anticipated by professionals in the field, this document is of utmost importance as it examines various applicable legal scenarios and establishes the requirements to be observed in the case of cookie usage.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
Every day, millions of users generate data on the web, which is used by companies around the globe to improve their offerings. Therefore, in 2018, a law was created to regulate the use of personal data by companies, and this directly impacts digital marketing. We're talking about LGPD.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
31 May 2022
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications